CVE-2025-24564 HIGH

CVE-2025-24564: WordPress Contact Form With Shortcode plugin <= 4.2.5 - Reflected Cross Site Scripting (XSS) vulnerability

Vendor Aviplugins.com
Product Contact Form With Shortcode
Weakness CWE-79 · XSS
Published February 14, 2025
Last update May 11, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Contact Form With Shortcode contact-form-with-shortcode allows Reflected XSS.This issue affects Contact Form With Shortcode: from n/a through <= 4.2.5.

Explanation of Vulnerability in Simple Terms

02Summary

Contact Form With Shortcode versions 4.2.5 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts into form fields that execute in visitors' browsers when the form is viewed. The vulnerability affects the scope beyond the vulnerable component, potentially compromising user sessions and data. Site administrators should update to a version newer than 4.2.5.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that run in visitors' browsers when they view the contact form.

Potential impact on your site

04Site Impact

Visitor sessions and data can be compromised; attackers can steal credentials or redirect users to malicious sites.

Conditions required to exploit

05Prerequisites

Visitor must view a page containing the vulnerable contact form with injected malicious content.

Key dates

06Disclosure timeline

February 14, 2025 CVE published
May 11, 2026 Record updated

Related vulnerabilities

08Related CVE